35838d27c601b97efbe98f3a7d316a8f

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1992-Jun-19 22:22:17
Detected languages English - United Kingdom
English - United States
French - France
CompanyName www.printerlogic.com
FileDescription Printer Installer Client Manager
FileVersion 19.0.33.8010
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
ProductVersion 1.0.0.0
Comments

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ v6.0 DLL
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
  • sc.exe
Contains references to security software:
  • Monitor.exe
Looks for VMWare presence:
  • VMware
May have dropper capabilities:
  • %temp%
  • CurrentVersion\Run
Accesses the WMI:
  • root\cimv2
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • PrinterPropertiesPro.com
  • app.printercloud.com
  • app.printercloud10.com
  • app.printercloud15.com
  • app.printercloud5.com
  • devont.com
  • dummy.com
  • gw.app.printercloud.com
  • gw.app.printercloud10.com
  • gw.app.printercloud15.com
  • gw.app.printercloud5.com
  • http://www.devont.com
  • http://www.iec.ch
  • http://www.printerpropertiespro.com
  • http://www.printerpropertiespro.com/products/migrator/knowledge.php#_Issue
  • http://www.winsoft.sk
  • https://jcl.svn.sourceforge.net
  • https://ofn-gw.app.printercloud.com
  • https://ofn-gw.app.printercloud10.com
  • https://ofn-gw.app.printercloud15.com
  • https://ofn-gw.app.printercloud5.com
  • jcl.svn.sourceforge.net
  • ofn-gw.app.printercloud.com
  • ofn-gw.app.printercloud10.com
  • ofn-gw.app.printercloud15.com
  • ofn-gw.app.printercloud5.com
  • ofn.app.printercloud.com
  • ofn.app.printercloud10.com
  • ofn.app.printercloud15.com
  • ofn.app.printercloud5.com
  • printercloud.com
  • printercloud10.com
  • printercloud15.com
  • printercloud5.com
  • printerlogic.com
  • printerpropertiespro.com
  • source.com
  • sourceforge.net
  • svn.sourceforge.net
  • www.devont.com
  • www.iec.ch
  • www.printerlogic.com
  • www.printerpropertiespro.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to AES
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongA
  • FindWindowA
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
  • RegSetValueExW
  • RegSetValueExA
  • RegRestoreKeyA
  • RegQueryValueExW
  • RegQueryMultipleValuesA
  • RegQueryInfoKeyA
  • RegOpenKeyExW
  • RegFlushKey
  • RegEnumValueA
  • RegEnumKeyExA
  • RegDeleteValueW
  • RegDeleteValueA
  • RegDeleteKeyA
  • RegCreateKeyExW
  • RegCreateKeyExA
  • RegEnumValueW
  • RegNotifyChangeKeyValue
Possibly launches other programs:
  • CreateProcessAsUserA
  • CreateProcessW
  • CreateProcessA
Uses Microsoft's cryptographic API:
  • CryptVerifyMessageSignature
Can create temporary files:
  • CreateFileA
  • GetTempPathA
  • CreateFileW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • MapVirtualKeyA
  • GetForegroundWindow
  • CallNextHookEx
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Has Internet access capabilities:
  • WinHttpGetProxyForUrl
  • WinHttpGetDefaultProxyConfiguration
  • WinHttpTimeFromSystemTime
  • WinHttpTimeToSystemTime
  • WinHttpWriteData
  • WinHttpQueryOption
  • WinHttpSetOption
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpQueryHeaders
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpAddRequestHeaders
  • WinHttpCloseHandle
  • WinHttpOpenRequest
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpCrackUrl
Functions related to the privilege level:
  • OpenProcessToken
  • DuplicateTokenEx
  • AdjustTokenPrivileges
Interacts with services:
  • QueryServiceStatus
  • OpenServiceA
  • OpenSCManagerA
  • ControlService
Enumerates local disk drives:
  • GetDriveTypeA
Manipulates other processes:
  • OpenProcess
Changes object ACLs:
  • SetFileSecurityA
  • SetNamedSecurityInfoA
Can take screenshots:
  • CreateCompatibleDC
  • BitBlt
  • GetDCEx
  • GetDC
  • FindWindowA
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertOpenStore
Info The PE's resources present abnormal characteristics. Resource PRINTERINSTALLERLANGUAGETXT4 is possibly compressed or encrypted.
Resource PRINTERINSTALLERLANGUAGETXT4 is possibly compressed or encrypted.
Resource TMAZEIMAGESFORM is possibly compressed or encrypted.
Info The PE is digitally signed. Signer: PrinterLogic
Issuer: Sectigo Public Code Signing CA R36
Malicious VirusTotal score: 4/70 (Scanned on 2022-10-10 10:00:28) APEX: Malicious
ClamAV: Win.Trojan.Qakbot-9955707-1
Google: Detected
VBA32: BScope.TrojanRansom.Blocker

Hashes

MD5 35838d27c601b97efbe98f3a7d316a8f
SHA1 226564af44961be31ea8c9637251e6e471a94e31
SHA256 0b57190a1151e5877be891c8241079042afd7536a5865229614a78ba2323b042
SHA3 e9b751250ab27f750d108fadb97c1c659ece04afb30856f5ed439184dfcf6a82
SSDeep 49152:5S/cAULSSp52F3tRxuaX5nwzwQy2rla5w+yYNghKBN:5SUAUxetfuaZb2rl5nw
Imports Hash 3279335e1d6332ecadddcb22373e4a8b

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 1992-Jun-19 22:22:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x201600
SizeOfInitializedData 0x9bc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x002002A0 (Section: CODE)
BaseOfCode 0x1000
BaseOfData 0x203000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x2a6000
SizeOfHeaders 0x400
Checksum 0x29ffa1
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

CODE

MD5 23f29193f3d9fcd3abd6465bdb5b7d3b
SHA1 0f913bf3f54fcdd06bbfbcfb74e7a53a39af281f
SHA256 50467383ed99e946f835fe5975f20f9917fe0107d3afd1a7e11f68ff60623933
SHA3 85d6897a22f4d36e23955e291f527078cdbc66eb662eeb86a6245144d3935f11
VirtualSize 0x201428
VirtualAddress 0x1000
SizeOfRawData 0x201600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50336

DATA

MD5 03be0e4fca94f04533aaf08a4a96fe5a
SHA1 2c50cd30220db2864f9007b1c5f99ea384ecec14
SHA256 2982f98115d1a2218ae6e4c73980f3f31b1145ca0befbd6fdf15b092c3ac5954
SHA3 6958422496725e5584925feffb6dc1d52045e7056d49597b5a68966a2c65e416
VirtualSize 0x88b0
VirtualAddress 0x203000
SizeOfRawData 0x8a00
PointerToRawData 0x201a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.27834

BSS

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x3bc1
VirtualAddress 0x20c000
SizeOfRawData 0
PointerToRawData 0x20a400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 384ee8fb5ef59d707dfe3e0130eec503
SHA1 d432fcdf8182e3f998edacd8c01d13de6d9bc8b4
SHA256 7ce91a000d75dabf57856efa1bc20d6f49117aa90e48aaf50a67f4287f6a08cd
SHA3 9786f647d249009c0a1c7697c6c81a820651920ef4260c9870eb1f31e838d98a
VirtualSize 0x4ada
VirtualAddress 0x210000
SizeOfRawData 0x4c00
PointerToRawData 0x20a400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.00508

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x24
VirtualAddress 0x215000
SizeOfRawData 0
PointerToRawData 0x20f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 1dbfcadd1539b6d5eb10fdb91d29fb38
SHA1 d92e5a847a3cb6a5f9061a7eaeaa35b5a9a4ee31
SHA256 a5b18edb3ec19d7f1f7adcfa1300f8b673769a819310c49a93f05563a6c2c80d
SHA3 3cab3d6f86021e9810b9725ad5135eae092a973bb85c593967325fc502bcb5ad
VirtualSize 0x18
VirtualAddress 0x216000
SizeOfRawData 0x200
PointerToRawData 0x20f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.20692

.reloc

MD5 9a3f9bd60d30fe788b5f4b90515d3899
SHA1 164646ff05be976595ba72d7a231d0c1f95f1baf
SHA256 fd7c385f37e72dfac4305c56ddace202a3aa8aa371f8cec4510761699bd10019
SHA3 c5f11bafeead32045e43d2c3bf09095d1f89b40c613b05a853045a53978584a8
VirtualSize 0x1c644
VirtualAddress 0x217000
SizeOfRawData 0x1c800
PointerToRawData 0x20f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.7497

.rsrc

MD5 580ebcdec89de671cb2331a7202aead1
SHA1 9b3c4402dc4ec81e4d45e3cde1a81d903c4ce211
SHA256 cc77a7a2633be443ba7c99f18fc98c07cac6f261fa267487fe3713bc067c6a7b
SHA3 0dfac85485c0219cb65e4ecaf7a4d6b02a0461ba21f297fd0523fb1974e54842
VirtualSize 0x71bac
VirtualAddress 0x234000
SizeOfRawData 0x71c00
PointerToRawData 0x22ba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.45618

Imports

kernel32.dll DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
kernel32.dll (#2) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
msvcrt.dll free
realloc
malloc
advapi32.dll (#2) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll (#3) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
mpr.dll WNetOpenEnumA
WNetGetProviderNameA
WNetEnumResourceA
WNetCloseEnum
WNetCancelConnection2A
WNetAddConnection2A
version.dll VerQueryValueA
GetFileVersionInfoSizeA
GetFileVersionInfoA
gdi32.dll UnrealizeObject
StretchBlt
StartPage
StartDocW
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetMapMode
SetEnhMetaFileBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SelectPalette
SelectObject
SaveDC
RoundRect
RestoreDC
Rectangle
RectVisible
RealizePalette
PlayEnhMetaFile
PatBlt
MoveToEx
MaskBlt
LineTo
LPtoDP
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsA
GetTextExtentPointA
GetTextExtentPoint32W
GetTextExtentPoint32A
GetSystemPaletteEntries
GetStockObject
GetPixel
GetPaletteEntries
GetObjectA
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileDescriptionA
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
GdiFlush
ExcludeClipRect
EndPage
EndDoc
Ellipse
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreatePenIndirect
CreatePalette
CreateHalftonePalette
CreateFontIndirectA
CreateEnhMetaFileA
CreateDIBitmap
CreateDIBSection
CreateDCW
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileA
CloseEnhMetaFile
BitBlt
user32.dll (#2) GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
ole32.dll CoTaskMemFree
StringFromCLSID
CoCreateGuid
kernel32.dll (#4) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll (#2) CoTaskMemFree
StringFromCLSID
CoCreateGuid
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
comctl32.dll ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_SetDragCursorImage
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Remove
ImageList_DrawEx
ImageList_Draw
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
InitCommonControls
winspool.drv SetPrinterDataA
SetPrinterA
SetJobW
SetFormA
ScheduleJob
OpenPrinterW
OpenPrinterA
GetPrintProcessorDirectoryA
GetPrinterDriverDirectoryA
GetPrinterDataA
GetPrinterA
GetJobW
GetFormA
FreePrinterNotifyInfo
FindNextPrinterChangeNotification
FindFirstPrinterChangeNotification
FindClosePrinterChangeNotification
EnumPrintProcessorsA
EnumPrintersW
EnumPrintersA
EnumPrinterDriversA
EnumJobsW
EnumFormsA
DocumentPropertiesW
DocumentPropertiesA
DeletePrinterDataA
DeletePrinterConnectionA
DeletePrinter
ClosePrinter
AddPrintProcessorA
AddPrinterConnectionA
AddPrinterA
AddJobW
AddJobA
AddFormA
shell32.dll SHGetSpecialFolderLocation
SHGetPathFromIDListA
SHGetMalloc
kernel32.dll (#5) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
wsock32.dll WSACleanup
WSAStartup
gethostbyname
gethostbyaddr
send
inet_addr
msvcrt.dll (#2) free
realloc
malloc
advapi32.dll (#3) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
netapi32.dll DsRoleGetPrimaryDomainInformation
advapi32.dll (#4) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
advapi32.dll (#5) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll (#6) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#6) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
Advapi32.dll RegDisablePredefinedCache
winhttp.dll WinHttpGetProxyForUrl
WinHttpGetDefaultProxyConfiguration
WinHttpTimeFromSystemTime
WinHttpTimeToSystemTime
WinHttpWriteData
WinHttpQueryOption
WinHttpSetOption
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpQueryHeaders
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpAddRequestHeaders
WinHttpCloseHandle
WinHttpOpenRequest
WinHttpConnect
WinHttpOpen
WinHttpCrackUrl
advapi32.dll (#7) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
advapi32.dll (#8) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
advapi32.dll (#9) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
bcrypt.dll BCryptDestroyKey
BCryptDecrypt
BCryptEncrypt
BCryptGenerateSymmetricKey
BCryptDestroyHash
BCryptCloseAlgorithmProvider
BCryptFinishHash
BCryptHashData
BCryptCreateHash
BCryptSetProperty
BCryptGetProperty
BCryptOpenAlgorithmProvider
BCryptGenRandom
iphlpapi.dll SendARP
GetAdaptersInfo
NotifyAddrChange
iphlpapi.dll (#2) SendARP
GetAdaptersInfo
NotifyAddrChange
crypt32.dll CertFreeCertificateContext
CertFindCertificateInStore
CertCloseStore
CertOpenStore
advapi32.dll (#10) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
msi.dll MsiGetFileSignatureInformationA
wintrust.dll WinVerifyTrust
Crypt32.dll CertFreeCertificateContext
CertGetNameStringA
CryptVerifyMessageSignature
Imagehlp.dll ImageGetCertificateData
ImageGetCertificateHeader
ImageEnumerateCertificates
wtsapi32.dll WTSQueryUserToken
WTSUnRegisterSessionNotification
WTSRegisterSessionNotification
WTSFreeMemory
WTSQuerySessionInformationA
WTSEnumerateSessionsA
kernel32.dll (#7) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#11) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
winspool.drv (#2) SetPrinterDataA
SetPrinterA
SetJobW
SetFormA
ScheduleJob
OpenPrinterW
OpenPrinterA
GetPrintProcessorDirectoryA
GetPrinterDriverDirectoryA
GetPrinterDataA
GetPrinterA
GetJobW
GetFormA
FreePrinterNotifyInfo
FindNextPrinterChangeNotification
FindFirstPrinterChangeNotification
FindClosePrinterChangeNotification
EnumPrintProcessorsA
EnumPrintersW
EnumPrintersA
EnumPrinterDriversA
EnumJobsW
EnumFormsA
DocumentPropertiesW
DocumentPropertiesA
DeletePrinterDataA
DeletePrinterConnectionA
DeletePrinter
ClosePrinter
AddPrintProcessorA
AddPrinterConnectionA
AddPrinterA
AddJobW
AddJobA
AddFormA
advapi32.dll (#12) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll (#8) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#13) RegQueryValueExA
RegOpenKeyExA
RegCloseKey

Delayed Imports

CASE

Type UNICODEDATA
Language French - France
Codepage Latin 1 / Western European
Size 0xedc0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.51536
MD5 96e9f308bfd868c479c7fd8e9d6ba597
SHA1 2bc75dfc0aed3307853979c753603859a8efff8d
SHA256 9ecbfaaa651402e78adcc68cd4dac6725ef859afd95dd8bf32f8a58309e8da9d
SHA3 a280d965c8a3e88e119e491bc4d3ded6f9ee87e39df88779a5d1169209c9255c

CATEGORIES

Type UNICODEDATA
Language French - France
Codepage Latin 1 / Western European
Size 0x7870
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.61662
MD5 d60840361711c3acca5d03632dc376c5
SHA1 a888d24d9e78b9333487cbbbabd35af05bf82563
SHA256 c8832f30b3ee52a56ab188e02f618662ea31f80c19a4294af367dac20fe88bab
SHA3 12fd707532b5d1e0367b688071748415eb6a731f60be2471e1419cbc0e3c10d1

COMBINING

Type UNICODEDATA
Language French - France
Codepage Latin 1 / Western European
Size 0x8d8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.06605
MD5 eff53143dce46b4a4e160532e95c8719
SHA1 f6512e4379e45d95c44ed759070011be1bb85c5d
SHA256 6faf42a5c9dc0310afd453192ef521756f5a51758dc656d1b28bd6d6c9733a84
SHA3 8368f2d9196227f4964f812bd74bb0fa14039d80a255a04ff55f48a38d193164

COMPOSITION

Type UNICODEDATA
Language French - France
Codepage Latin 1 / Western European
Size 0x3e84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15624
MD5 505c6088819d0c46d5e286ccea8fb4b7
SHA1 96e0b9155e0a4a320d43ea239bf4173bdcb92e12
SHA256 46550617022eee808cc725b97a21fb5523a4d1f9d60d4752eb813ff037698b06
SHA3 2c8e3ed5e4626414f430db9b29bef2f8571b15657d276d86b2d5ec875dcacc54

DECOMPOSITION

Type UNICODEDATA
Language French - France
Codepage Latin 1 / Western European
Size 0x7498
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.659
MD5 67a9c9a34e7de2fc54ac1c140f656a68
SHA1 f3d37c457031b7459b4fb55636bdada09abdbeaa
SHA256 1053f577d87e9a341c1908d76332855e7a26d422f738fd7efcaaae2fc35ba7c3
SHA3 252b65790fecf4dfb2e4ec40db2208a4fc13352e0be66de259f1a6a6914c84fb

NUMBERS

Type UNICODEDATA
Language French - France
Codepage Latin 1 / Western European
Size 0x20a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42541
MD5 d36dabb137f0933963c0ea32f6dc0243
SHA1 b8b82f3c4c7287457d22167bab67af8f8534a705
SHA256 14d380c8ad4de83fe8dbc6b1e88a6ef5891d8b15e01208a8067be4509c895d86
SHA3 c41ab8178b83cd7d0a751e391a81e7815179107433a666fa58dbe9318db7195e

1

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

BBABORT

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBALL

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16995
MD5 f8a9b4a8f4097cea6a482026484c4d12
SHA1 2057a63edce2cbb165512bfad326728cf1053d60
SHA256 46cfc44afa8ab31ae3da35fa8346e4c085c441659d9992b09fc8ad517f2b289a
SHA3 f3852a8bcb1b38f498231cca2b0427af6c4c52886f92f980968d40fd8e8c5337
Preview

BBCANCEL

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBCLOSE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.68492
MD5 6c2fba077bd332b3a48d6b5e43fe4a22
SHA1 e7d12e9fd5659881742773884db8ca537765dc81
SHA256 f8e1696801fe89b88936ac4226cea03bfa5aa345aa33ca982822ae7fbc6557e2
SHA3 39193ea4b2ffb32f16c75ca88ca20465a374cd928aac9b4b3ba5739bbb6222de
Preview

BBHELP

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88085
MD5 1021657335ba4838db07f5231723df3b
SHA1 68f04f6ecbf628029e4e0061392029edec2b0e43
SHA256 cb7421b5c6af74c3159c361f3bb78bba8a488d8979d1250e106fa96cbf928789
SHA3 888ed4f8473561552d848c3d6624e2331c4ec7795bc5001237cb752b96e4929c
Preview

BBIGNORE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29718
MD5 098b5f6c87471f5a83a4e55a6a036d6c
SHA1 e16d9186ffa72cc3e373cdf8e40f9e570f0082e7
SHA256 41f05a4df5f42d92b879493d51941de342d36460fe15c0f3b63b2b706b928fef
SHA3 7939e94342a45e6742dbf7c93f5b42fb861ac81b1fe5e8e04e49c0421338b2cf
Preview

BBNO

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.58804
MD5 8832519641f28981f87e1b3006896eef
SHA1 916eaafcf9ffb12bfd6338419bdd22764778ebbd
SHA256 81265e63c89ee5c2e5126452e22f84e9be9452449f3e5959ab6d346cb58b2bde
SHA3 39743ce838b215420cbb732e107e4c45f63384dcdd5b830d15097fa06cf32cc2
Preview

BBOK

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

BBRETRY

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53344
MD5 7daf7522622a4fe823701fd2ff6f4996
SHA1 89f40bad3052afafbd71e80c07b928ec1aa7f4e5
SHA256 c925e4a8cbf6d42dbb1220a510614df725558f8d843338982bab8c4e020f6429
SHA3 95aa592de7b91edb5889cf5f9a7b042d3b6f6910bbd657ba85632f0d0ed557fb
Preview

BBYES

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

CDROM

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78825
MD5 6bb98462b4b00776fd17038cbf1fb4bd
SHA1 f40205d022d824e0b7d930151138991504af3dc6
SHA256 4f72c53f3bac49ce0b7c248152479a14e383a90c9fe95edbddec9f03784ca698
SHA3 2e951c0dc6c1e7540825793fbf48393c33a7156ba8a9ce6343a06323ef1716aa
Preview

CLOSEDFOLDER

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01477
MD5 7a7f1740c64d8b5af56ef7611410255c
SHA1 df7641fd3a5588e182515b337dcbbd28f2de12ab
SHA256 d20c1e7cdff419e1efe08e1b91b4c0d772f7436de618045f7e0fdb3afb662849
SHA3 111928d2405474821d76f758f1ba2dfb15368f64bbfde0644c9ec7acc5f56c9f
Preview

CURRENTFOLDER

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97986
MD5 53466cf475196c6a883514140b1253c1
SHA1 02f577f238ea87b3400ec0ced2315d53cddfc7d1
SHA256 0f5248f16fe2b1e73aa9be760a6f0bef933dc09e3cc6d8a8958eae1ce0bd0f97
SHA3 e38ae4779212d26cd9f3f9298910aa52dbbbce2527673aa9ada7de9deb1a817c
Preview

EXECUTABLE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.96393
MD5 d623fd4c67881a744b9783e77cdaa9a3
SHA1 07fd1454decb874d847cb6e3a847391e3b03865a
SHA256 4a217ca811d9c29363ead1d67b7ffa0f6e8b8e1d1a068730f4f7d557c3710b44
SHA3 2aa8c8713c75f32e131b449444a6b570ee7be8da50c2f7e8a499cef693339e85
Preview

FLOPPY

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63812
MD5 c3a2737f14f437f54cbf251782ae0a45
SHA1 e0a402c41f62804664b9d9cb9bae9615bf60f5ed
SHA256 2cb60d7d674640457497f54b82b42afaa8a2cbd7c28a1aae35f128b4471cfaaa
SHA3 eb1bb0ae168e1645292c6759be7ba322451b7035d87f01f8bf0f548290bb1830
Preview

HARD

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62043
MD5 47957e26414e5a0cf93c9049b1a7f2a2
SHA1 08a70125bb3cf069d224c94dd4f4632b8f671a61
SHA256 a36fee3ac0a24b86169997e112d55de38ae2080815d2104c73bc90ad4eff5cbe
SHA3 59409ff1a314a69758371a1dafa7f175812eb3821240ff5b25b7b881b9d58deb
Preview

KNOWNFILE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.83217
MD5 7a6c4028ea8bdbe916a592614cb67a33
SHA1 e84fa7f028b79b4c641a2d66ad1ad296b7e6a262
SHA256 d8444a0e4c91df51a151d4c64256e5d5f62a3e4a5b17ccb9778422f0e01223c3
SHA3 de4dcc10f2110aa3f30104c8ef6a447c8fb22789a236072e61e38d5e16d0e0c9
Preview

NETWORK

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73457
MD5 30e739f7ed3dd033117260d97bb67e99
SHA1 b97adf513dd432cf039cd9425caf9b3241d7d233
SHA256 caf10784d936136cddde6b4489d7ffdc6098f8050a81c7e02d1ebdd9878cff15
SHA3 1511f9fa160bee36e6099269dade08d1a5709a22360ccbd4060fa6b54b8fb7d4
Preview

OPENFOLDER

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.0519
MD5 9b7d7f0031cfa6a137ff6436e59986fb
SHA1 20eb56f55581540919b119113b567bec618c3f95
SHA256 e086586402b8c51192766a01a37dd2f2b4b657bbd4d5b721f1eed692678f6ef6
SHA3 86a19763883baaae65d79b7e3c64525f16b942bd1187792bab8f56f7efaa2c56
Preview

PREVIEWGLYPH

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85172
MD5 48276e8432af5a23af78e1d23de8ef5a
SHA1 12fb57606d03e3fe28263e3e9e96b4eedc79aef7
SHA256 78507a772de646626b196a743cee75b298a68c33a0fd482842071519d59037b2
SHA3 1cf31d53c7ea5dbe90181cb2db39ce6cd21484f5495b0af59f5c6164d9b3d3d0
Preview

RAM

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73213
MD5 0ad765e61ab984673ce3db3a91fc6182
SHA1 2b67d4f1eec717c3aa2472db56ab4472c96b742f
SHA256 5bea8ae9edb158f767d478703ce5153b8773e1e0390fa2c4af83f063c6c2f1fa
SHA3 deda4d692b33e267292ba10effd899736e090a1af7f55028cdaa0ef850a85945
Preview

UNKNOWNFILE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.50975
MD5 307c6180ecb5efadfc8d59bb7dc28a5c
SHA1 8cd2e11eefecccd0c1414ce2b548c4fa82621dd4
SHA256 6af26f85073e8fce3b9ab49acbde0b702f68ec078be72e8aeca66086947a885e
SHA3 3e2f18021c6974600d7e8fc8064bb225657e4aeb0e28b7fdae034c6e938e264f
Preview

1 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.25282
MD5 9f855dacdf7f2ede47534cadc4dfb967
SHA1 effe5c9919de75496779a00e9010a4319ab2c58f
SHA256 1475386264956f1c012d4700b7becb86a5b5fc81daf68088ac05a557d686f786
SHA3 847ea02564c954477b2baa8c6e781e029dea32aaac61d252112bccf3baeda6a7

2 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.6978
MD5 54eb18f4df054cdf6599fa3cfd5882d3
SHA1 af59270af4baade95d55ab28a7b22c032fd75807
SHA256 781f54a9b2b9ccddfd973586653b8695efe16795f936a718f1f09cd68cc31f22
SHA3 f99ae18d635433302b5ca301d9cb3668ee080f229ff379a82d913da61264a9ca

3 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.60119
MD5 27e2c8d6ce43cf53b20aa9668e741b83
SHA1 92cb4d182c4f23dd80b26d8b6a4e98d932af055c
SHA256 af253f359e7174a56fe038cc5670562fe09f7378361edfdbad7a75910681feb0
SHA3 b6632b36c213a052968f249ba29770b13c728bb42fe48aeee2f34dda05d1e009

DLGTEMPLATE

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x52
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.5627
MD5 db949b51eec31f37281a7fa424a3e158
SHA1 f61214ce31a91d174e77f12c90f18ddd4e265a1d
SHA256 771f64afb45a9edc8c4f6c5b2039f9b32623cea53bf0cab5bf1f371cc5d1abe4
SHA3 4a2bc09771734352d594a48fe2249ca0697c471d80a4001f60c6d86c46b6319e

4059

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xdc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87587
MD5 94d766682ba79c1fe314f0e116d3d3ce
SHA1 4c09a49bb957164e867521b35a9f1d1d5f1145b6
SHA256 dcfc8578a4a7e35462c2c0fe48fd126a84fe9638e56a6630e3093f492466072d
SHA3 b7318edd9abc9c1c7026edfbbbc71296910dc9cef3dc2489e222a8b7f13374fe

4060

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29222
MD5 e52419cd7e7c4195d530466e4e08ecf1
SHA1 8d3708493f9593a6596dd29f2be29c73aac0773e
SHA256 4b00be76b2ef948b39245603817668a85dba5e75e228baab688af35663136cc2
SHA3 0fffaf7f639ea1c08990d10fb9bb1893a8ca263a16443d38c27a35fafd4d1bea

4061

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14033
MD5 6cf4eb07fed3b0af6a72dfd353b2cfe0
SHA1 b3a998a5f9cb9f599bc1884527a50f264235d4f5
SHA256 09bbcda532f995d5255296cebc65b1a096c140d736cb77d107d01a563aca086f
SHA3 9e288dbf0b4bd74b8b2876626506f7da22bd855348ced688e654b2e2fe4a9d33

4062

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x324
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16527
MD5 eff2597033c63d450633c2ca2cb7dc0b
SHA1 1dae7ba45f8077f43a09f1b244cd9cfa9bb80336
SHA256 adafdb9a673b4d879dfde92b011b6aa64c414bcb6060ff023b8e49c51062da02
SHA3 0e223f823c8c0ac0cf78ab2faddf00ccad13bf5e4679354828a78e5d1e24dec4

4063

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x28c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30215
MD5 a04de6e9e71161a5a08e28766824aebb
SHA1 94cb48dbb062dfab0ae1b57b6f659108217068b6
SHA256 3096ea5eb946bbf37b625dbed344d1f665db1436109346b82552dda48e9f04d8
SHA3 1e75de65155d8867eeec3b5bb3f7254ab432d73f27459fd5465882291505c538

4064

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x13c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19707
MD5 067e70f368dcedb3d789f733658e698e
SHA1 e4584be4d61619718c18c5c21122429eb0c1f056
SHA256 be3f7e8ee7cf5bf954c61a016a833e1a47dcc29c0c89dee857c90289939f5fef
SHA3 772d60d0113a5818fe577b849052bf58073c4a7525fb5feed233358343f6ceec

4065

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4b0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3328
MD5 081fec1c80d30cf91229739757ff1ca4
SHA1 a063dfc33098678feb5447426c72e78fa9bbc6a9
SHA256 ee772b8c97273888430beb5d4c369e6d0fd43858afdeecd9ad9c268c4713d4f7
SHA3 1a6fe491f520485d1b44a68378b487e87c8ada8a0fe53bc62df3654659eb3c72

4066

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2f8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4933
MD5 51442cb22a671e009d956f2fb3f66bc2
SHA1 871a7de62f537671a6d381f56e9d2bd9be3c4dbd
SHA256 c80ee0e8054ff2721469661b42ace069b05bf5167b7d9e0e3f54d69c8cf31f4e
SHA3 2ff477701e12eebd4ba25cd8b514b5fa69b704fe9a431683071da3d1fb256131

4067

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x24c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44382
MD5 0dff3d0fb9f51c94d13eb963d26ca192
SHA1 c0723abf8e764bbbdd6037bc813bb3558ee22787
SHA256 06eac9816e88a1810437fdb720d999465c904c71cba0cc5f98d78b56763fcfd5
SHA3 3191ee9832122e4aef827a52400c38bbde81642a378b7cb94ab49082e73be342

4068

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26826
MD5 31484a9cdf69ac609c3a3c68e6c1c567
SHA1 250fb7ae61ce287fb10dd5a22069467ea01c3ae9
SHA256 e0653b06b017df14c2741eaf28cd877f9cbe166b86edfa102a325199e93986ab
SHA3 c3aafe5b9048d297093ec6ed4964feb810317f00b51e4a5b927c3627659713bf

4069

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.1226
MD5 022ea876edc419354509a74a922c98a4
SHA1 8753944d8e7d09efb2c485ea24dcc8bf2cfe4179
SHA256 91d00e302f1418d30e3bdcf9a521bfd8e3457d755a044cdf988a1242cc2e303e
SHA3 c2d7afd09af7a5359129978efdaa81cbef88a4a63aaa1d998f547811cd3b040c

4070

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x370
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26063
MD5 b3b9a2e540c6509d47a5f755be46a595
SHA1 6d33688ad6190e1e72679ebc93b8478126fe136e
SHA256 eaa195600a5551bcd8fc4fd39ea52df8579c88a1349c5cd4dfe9a1bec7ce7b72
SHA3 fbc2a1896d56860551a7f7f383268fe16ba6c146b60742be7099b352e8fb7991

4071

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x458
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13939
MD5 0ebcb0232c3a0beef68518a1ffbfd3c5
SHA1 5f860994bbb79c34b792ff6455890e6683e04f5a
SHA256 fd250f47ef9c84deb2081406fb1a627860c234e6b9c103b6f32f5330464911de
SHA3 c273f00a950ed67ecaa6683dc18ccc71678b184b827f9bc5ca4263d766a09b77

4072

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x5c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20329
MD5 af6013475a2c1cc83945dd6c72af321c
SHA1 f6d45bd224f713893dd9eeaffe84db5555950a84
SHA256 e2f24fbb51f8aff19c8d251a5fdba7f99d46d2c8dae74336ef9e306f56edfb70
SHA3 6729d42eb6ce5e9dbf6ffd695e451cfab2ec230e6be9668ac79d076d4cfb8d45

4073

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4e0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38336
MD5 54350fc7e10ea886cded9eda039b0115
SHA1 7486fbdb6984991e8a869377690ac4d7c083c4d5
SHA256 f970e44b3f83e2773e1d2388accc5429c788d5cea3f324b537449c366833d342
SHA3 08be51af0be33af4b7300d7a96cbf3e81a8945e88c7c046bf053c504801bb2f5

4074

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x964
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23181
MD5 1dd58f93c58548df2236ecb273848642
SHA1 065c884b585e1d97f267b6db8207d0246440964e
SHA256 998e9c79884af38c1bc6714c581918e06c4a40477534da829253cd0628829523
SHA3 69e003983dc9a3dbb4833db3e7eb39a79b95b48f8180420b977c284d6e2fc2a7

4075

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x75c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27347
MD5 fc356eb82901c5746805a4021fe7aca1
SHA1 f184132857005133ea0f8ac2e04d4e3cc751c290
SHA256 40fd5f083b4b9bd06408cfc051ae850fc23b78cd308f23c4ea769504c7cb1c7b
SHA3 fa94a2956c5a964ae9e658ca9b3703e058d35b19f76475249776df213536ea48

4076

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x89c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23846
MD5 35c42c23b576be553c7f76905342a083
SHA1 2a3f65461316984bf1527f9bf6e95f000562576d
SHA256 6456b709dd0534209d6a8f43bca82613e4c611f2ce3bcd575d75cb81e27595a0
SHA3 9d178a2296282aa4b71f5fe5d8bd94aa63c7c68e17948037b0be0f63eb8d0cd1

4077

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xa60
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19601
MD5 fed234a8989fd8e113c748f7d799a2c8
SHA1 184f8477da4599d173e5b0cbdf111b9cca350ee7
SHA256 ecf0fffe18fad3bff5fd044829fbf8b5da558c9e5e8ad73fc3cfe7cacb98a4e6
SHA3 b882c91981e9270d743cf39f94802c607eaf55a2d515641d273d9f4888f60653

4078

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x688
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31109
MD5 535ebb86f6ad7752f623d5d0d6d16c11
SHA1 5a5ddc6b030605340c9ff48fb34b8f27bea992f0
SHA256 68f523e251f53e8c373803518cb235f85e967f2737cb543a0fa0afa391dc0c4a
SHA3 b99778e870a31f02b7036bdd1970f72384227ce59e677d529fc9f6b682f6e1a6

4079

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x218
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24654
MD5 61b84b8f57129050b612bdeee7c64414
SHA1 754b4204dad6e6d90feb1e2ed8debf6598ad9bff
SHA256 5a0354f400b1463d7ba9295a237543082e1c1e3244add6bd45957d2ba046e554
SHA3 dfeb24f715999c52553ff1531e0092ea65cf6c3bc9abee29353c720ea2664f2d

4080

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27601
MD5 f4a4b10d7ff827f0a9e21b06706be97e
SHA1 999b14eece9eeb2145f6bae04e886d4ae135a449
SHA256 83f780ed499b9006d6b2f018c75d10c11cb631a9763d842fcc8e4a6732b90a10
SHA3 cab79b55538bff3ed5fb22105c99104de0447da478c5777656cd1c5aa4671eb8

4081

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04775
MD5 410d6e935274674f3171c3526e2ce915
SHA1 8f2bdaec9f363e6b24d17bf1a2f9ef53f7f9e58f
SHA256 a5e89b1a6a6918ce79a3e247e2c3d062425c8cb56c0ecb308e84e2fdff168a87
SHA3 cd11ee51451050f7e19230cb1e3eb3fc4fdfc436e3ee412a52a16f05ff00d3f1

4082

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x348
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24316
MD5 5cf3de733cd2b9be9e5602edbb15ffb2
SHA1 c91c88a2351f9ca5322f63f6c1d5b8a81063c1fa
SHA256 2db4d77a1a2f79a632636e826322b3a30f9b110fe394d69f48acd6f269abc649
SHA3 155952d90f9575c228ed38b6814c18517961fb7057d9eb4824188400cfda7441

4083

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04708
MD5 eef78350fba28825dbe8bcd61f4b0237
SHA1 b2dc4b88dc8d6e1c819fa6052aed4331df6d4e70
SHA256 bc513d57ad95cbb305ac46ae360462e61754d10b6857199ceadf5003269a2110
SHA3 c36dadcacfef902b664746f7cf78aa8e8c3d2658ec395aa3a041f7eabb0fc1fb

4084

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x100
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08557
MD5 801f865cac1970b96d910c247aedb0d7
SHA1 dd099710d9952184a9c7e66c08043e657233bf3b
SHA256 84ac61e9857fc4cd7d4d56d7cd8e0ceb8b65b34287eec35f935b74924b1bc262
SHA3 fbf94540957563ff71bd37505d606233cbe071df9afcdd12855f2c39f387210a

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x238
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2612
MD5 e6e6d01c7a0944bff36b2722055b7337
SHA1 8158c50e72759a408d6efe103b4b49a9a2a8b1d1
SHA256 018def4f6cc5a7cf613ce89c3d965734ba04403395f03458bdd62692b25e476f
SHA3 a76ad45b8dd2b7ba2ebf0354a4e38e726df57b339893771f4ad7d54aad959c76

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x400
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2261
MD5 6b84400d5e22d6888431d828643556a7
SHA1 a9e002e419694791007a12d343bd838a72f53878
SHA256 8ccb381536aa26508564406033a55c93410c1607f8d05a3682d84098b3445b00
SHA3 b56f2e25f639042c37135d1bab995d4f7f07bff299b582afb592898e40617bba

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3b0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21314
MD5 7cd105c43d97fa2ec4a0f93d2a7a1377
SHA1 20879553a3012578e3d5f63de7d55af4c5dbb1da
SHA256 2f2a5a1cb7099197e46e7649ccb0fc8289f436d00778a0da5b8c96d062e35f66
SHA3 327a93da5db492c8b27555b52e8233179451d88d5f47a737caaa493e22c7b42f

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3b0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19939
MD5 4110f0bfb7a6d1d4de1cade00a01e79f
SHA1 ccb6e7aa6192358093418ba7b795979821723e00
SHA256 0fa6380a6fe799be7cbb82e0bc9f1959f06d855dfe50ad16df24b5f6dd62a55e
SHA3 b98ca9d1a1b3857ea15c9100bb684618746c90edf0aeb406ede0feb5dd9538ff

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21172
MD5 c896ca0008771f2dd622b8873c86ff25
SHA1 268ccc5c5f4d3d5e8af9d53f3d201d64b2f7bc32
SHA256 9150c31751dcbbdc5d062b602a9e7173464f0b73195772d1580ed704d2ac6da1
SHA3 76b4f497984a7d2b264b3bd0c616e2d2cf74fadc6b297404bac9b49979b6150f

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x260
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2425
MD5 1db98cf10894f8b09504f6bd5160e47c
SHA1 4252d880b4fe65eb6fdff9b94977cff8a9800a82
SHA256 61780f7920f424267e6ed09818603f0eda37d4a0e8fda90d72ac99a6f8869dbd
SHA3 9749eb1f09c5038c2d7bfbff198809cd2975f9200bdc6cb6419fd40013fe4835

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02839
MD5 64ca638c231c4a48d36284c40a0a2b78
SHA1 88c2784c8af158dda6cc6b9e0747fb4a25d5825b
SHA256 b567aba145ad2de8c26eb7288ba79970348f46a67c4e03013679862900452cf0
SHA3 213e14599924e64e9312bbf050ad2b867ce479e9bfe6a8345ea5cac7c5cc0d86

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x198
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20724
MD5 1187b293a853273d07fa51d178142937
SHA1 7518834ec4ab059bed837cfd5deecf8b9d8a42ad
SHA256 71333097093b700b65adf8cc689d36ca26c42cb733890690aaf32f5fdcae4f1a
SHA3 dd1251e3a98c0db1462cc0e596cdb28f57120931a5774bf03d45b2c5fe2f3c92

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x428
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25438
MD5 988aa0537972b7eae4373b97b046d8c8
SHA1 87fe95c7673b4f8cd710531fafb211d667475b45
SHA256 a8e4e3e739b4ed3e10c495c781557b4a6e0e83c9017a79c930f61834290e3d74
SHA3 ecba63271d290cf9f81ef1a2f2ff98b8da2ecab44aa3df308a42632dc458ed55

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24557
MD5 3897b75a909f48b390686cadc26bea94
SHA1 4717154d4fffd9af583e563bcffe083b27431437
SHA256 7a5a51bcb2cc1ea6e073717e37e305de978296a5ee949da16928a931328962b6
SHA3 ef7e8373f9969c962a5c79c9efd902008fda55220c6915fd4b1cff8c942f6eca

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21036
MD5 02e087ca69d12b5e3e54da017cb366b8
SHA1 2e09caa0c0fed0904e53ea86b1fdcf0873e8cccb
SHA256 135ab2924207a5e9f1642628827123430ac81d63ec6e2bb3b19185060b967e41
SHA3 1f1548e2f46555c5201e8755edf58ad17c0fbc83c9060fbd23f603e9ab4d5981

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09477
MD5 11dcdd905b943008807d85bd2b0423c8
SHA1 4bfe3056385b90a5a050fcc73a3b917ce97cc509
SHA256 f4a3dba56eeb2242ef3acd717076fee39ebe406ef4018ca57aa70e0c20e9ba86
SHA3 c4afe6cb23b3e4af3daabfc40ae18c5fa351ebb288852fd1247b620b79a31a86

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

INSERTEDFILEDATA

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x78
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.93032
MD5 3cdbcf3bb2490e61eb534959241439b5
SHA1 a7e8d9640d15d24e84f08c8359d51cfad97ad8f3
SHA256 58042577facce25babb411b7376b99d7a94036a68c21b4e75c47dc1c5f34327c
SHA3 a8669b305d77dc521dc00bcb7298a95e4892c6c2635b1cc268fbe4780acbba88

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1b88
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.3188
MD5 bea924ecd65ca6cf44a082209c8e037f
SHA1 0e8ef543308b341fc6520422a02b797ae4ef3a06
SHA256 f77e8b74f849b20e31d96fabe64d78c8019cc20816a0adddadf6ca86c1428183
SHA3 02b1fa857fcbca9c787c2b1b722718c865a84d2eef371f9fa15db3400d1c8d1c

PRINTERINSTALLERLANGUAGETXT4

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1b603
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70828
MD5 ddf265d4ea043bf94c67a40b13d786ec
SHA1 b673470397237b572f29bd33dcf3a9e0e8ed2019
SHA256 0473aeb18da9810c0383eab0d15023623ca86c5dd3794c2a09e52160480db95e
SHA3 67c522eddd22c72a32d7bff172a3eca0412e07682dcd872151f8d73e6235aed0

PRINTERINSTALLERLANGUAGETXT4 (#2)

Type RT_RCDATA
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0xdec0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70925
MD5 8f04f4fac756e42683129deff7cf72c0
SHA1 3ef2c09c577b38bc051b1ff10760d93c9684306b
SHA256 0036fc7c959ca0dd2cbd0416b0a241a1563ecbdbf40e3df241f5f3708b2ce07c
SHA3 7c817d79cadce4d10c77319827c9dfd960e3cec574d2a2bb3476fe19c0801da2

TMAINFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xac5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.51908
MD5 29a01ab2106961933e099f6d7ec7bea6
SHA1 8b43b13baef3e142751707f3ba56420ecce8d1fe
SHA256 26b22e8c408fb29172e29705132026a59dc81efce2d48441c6f2d5e867eb262b
SHA3 15a83f9b783f81d68d4083d4ec8dfca3c7ab8c3fa57bcc86b9b529a6298af063

TMAZEIMAGESFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x11566
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86988
MD5 07bb86a2f03434511fc669d4d30629db
SHA1 8391509fa6c940bb66c640a35988e0d6f16680c6
SHA256 cb917b490af5de3a4998c7752591442971cf7e40c8dac01601e7d2cecef5f7a8
SHA3 18ae861779cc1ee7718519474aaa8541b2ad15713b93f2a2caffd0e243f88fbb

TSERVICESERVERMODULE

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x11f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13835
MD5 63493682fb88471c0a65d9b8fd40b14b
SHA1 609c9abe26d59e42d1cc088661fdba0ae39dc8ee
SHA256 b907f2776a615df1ada6f4c7a948baa53d7209ad4cd6761aa5e72a0c1167923a
SHA3 8abbc95cf896192e625a79ceb5dbd698df1df5fd6dae13bfddb7e479938475b9

32761

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45849
Detected Filetype Icon file
MD5 409e1724611e0bc39356e2f58888db55
SHA1 c06c0e66cc2f7956256e2f018aa0294bfa914960
SHA256 6ab18c3b81a5d30c5a190a4504cae807d73b1a4d02d56ffddf641abbb62b7210
SHA3 315b2ad40793f4ef885ff4c878169b02c62f619b57780a98a76c8538cd0ee5c9

1 (#3)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x288
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29185
MD5 856417f9ace56dd6587fdc0c78ea5e53
SHA1 bb625b9b9f8f0670ba12740d9e8f90afe98661b2
SHA256 f18527c58fb6a5db96027c7bc0cde737174620f85ccbbec830ef0bb10f923126
SHA3 9c297a03d68091c7c255e2c8be19197029ca4449d1abe29967f6beaa39b1d80e

1 (#4)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27222
MD5 7edbb6ff8a4666428089329cb4a64704
SHA1 17a1a87be42b59a97ee9c54a3097a945e3036707
SHA256 3b87b527757f3f396c99c29212f402c9f1928d50f79d6e00494e6d3284aeb573
SHA3 f398bb15ef0c519f56f716ddbbe547021500c3ad3aa15f411dbb809b4a2040e3

1 (#5)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x351
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.1448
MD5 e14924e392d85085025ca090002b605e
SHA1 df2f833fb7aba8600f23c26311511c966ed8b14a
SHA256 5211a4bb6055c0f562b012b1291b5bb8063b0e202eb1a6bd884bf73dbc180835
SHA3 a5e0c61f35b9c9c5358f825ac9c2b076e1b287190368467ff57432c8d2db0d6e

String Table contents

%s is not a valid BCD value
Could not parse SQL TimeStamp string
Invalid SQL date/time values
Too many levels of symbolic links.
File name too long.
Host is down.
No route to host.
Directory not empty
Host not found.
Cannot change the size of a JPEG image
JPEG error #%d
JPEG Image File
Field '%s' is of an unknown type
False
True
Parameter '%s' not found
Unable to load bind parameters
Field '%s' is of an unsupported type
BCD overflow
Protocol family not supported.
Address family not supported by protocol family.
Address already in use.
Cannot assign requested address.
Network is down.
Network is unreachable.
Net dropped connection or reset.
Software caused connection abort.
Connection reset by peer.
No buffer space available.
Socket is already connected.
Socket is not connected.
Cannot send or receive after socket is closed.
Too many references, cannot splice.
Connection timed out.
Connection refused.
Bad file number.
Access denied.
Bad address.
Invalid argument.
Too many open files.
Operation would block.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
Destination address required.
Message too long.
Protocol wrong type for socket.
Bad protocol option.
Protocol not supported.
Socket type not supported.
Operation not supported on socket.
extracted
freshened
moved
replaced
logging
Invalid Gzip
Bad CRC
Bad File Size
Unhandled Entity
Winsock Initialization Error.
Set Size Exceeded.
Error on call Winsock2 library function %s
Error on loading Winsock2 library (%s)
%s is not a valid service.
Socket Error # %d
%s
Interrupted system call.
Ratio (%)
CRC32
Attributes
Format
Encrypted
Time Stamp
Size
Version Made
Version Needed
Path
Partial
Executable
None
MSZip
added
deleted
VMS: Failed to seek in swap file %s
VMS: Failed to read %d bytes from swap file %s
VMS: Failed to write %d bytes to swap file %s
VMS: request to write too many bytes [%d]
BBS: request to read too many bytes [%d]
BBS: New position is outside the buffer
BBS: Invalid Origin value
BBS: request to write too many bytes [%d]
TabSlidingWindowStream.Write: Not at end of stream
TabSlidingWindowStream.bsWriteChunk: seek failed
TabSlidingWindowStream.bsWriteChunk: write failed
TabSlidingWindowStream.Seek: invalid origin
TabSlidingWindowStream.Seek: invalid new position
Name
Packed
Method
Select File Name
OK
Cancel
Select Directory
Enter Password
&Password
&Verify
*.cab
Cabinet Archives (*.cab)|*.CAB|All Files (*.*)|*.*
*.txt
Text Files (*.txt)|*.TXT|All Files (*.*)|*.*
*.exe
Self-Extracting Zip Files (*.exe)|*.EXE|All Files (*.*)|*.*
VMS: request to read too many bytes [%d]
VMS: invalid origin %d, should be 0, 1, 2
VMS: Cannot open swap file %s
s
a
External File Attributes: %s
File Type: %s
Text
Binary
Encryption: %s
Encrypted
Not Encrypted
Unknown
Time Stamp: %s
Made by Version: %f
Version Needed to Extract: %f
Comment: %s
*.zip
PKZip Archives (*.zip)|*.zip|Self Extracting Archives (*.exe)|*.exe|All Files (*.*)|*.*
Reduced
Reduced
Imploded
Tokenized
Deflated
Enhanced Deflation
DCL Imploded
Best Method
Version %s
Compressed Size: %d
Uncompressed Size: %d
Compression Method: %s
Compression Ratio: %2.0f%%
CRC: %x
r
h
FCI cannot write file
FCI close file error
FCI file seek error
FCI file delete error
FCI cannot add file
FCI cannot create context
FCI cannot flush cabinet
FCI cannot flush folder
FDI cannot enumerate files
FDI cannot create context
Invalid cab file template
Invalid file - not a cabinet file
Stored
Shrunk
Reduced
Reduced
Error truncating Zip File
Failed CRC Check
Stub must be an executable
File not found
Invalid Local File Header entry
Archive does not exist - Filename is blank
Error reading archive
Invalid archive item index
Invalid archive size threshold
Unhandled Archive Type
Spanning not supported by this Archive type
Error creating Log File
Error Moving File %s to %s
Cannot load cabinet.dll
FCI cannot open file
FCI cannot read file
Archive is busy - cannot process new requests
Insert the last disk in the spanned disk set
Insert floppy
Specify spanned image file #
Specify the last file name in the spanned image set
Image file name
Spanned archives must be opened as file streams
Insert disk number %d of the spanned disk set
Insert span number %d of the spanned file set
Cannot update an existing spanned disk set
Cannot make a self-extracting spanned disk set
Insert a blank floppy disk
Stream write error
Directory does not exist
Cannot inflate block
Invalid Stream
Could not obtain OLE control window handle
License information for %s is invalid
License information for %s not found. You cannot use this control in design mode
Unable to retrieve a pointer to a running object registered with OLE for %s/%s
Unable to load ActiveDS.dll
Could not find ActiveDS function:
Invalid file - not a PKZip file
Cannot extract file - newer version required
Cannot extract file - unsupported compression method
Cannot extract file - no extraction support provided
Cannot extract file - invalid password
Cannot insert file - no insertion support provided
Invalid Reduce Factor
Cannot insert file - duplicates stored name
Cannot insert file - unsupported compression method
Process aborted by user
Data TLB: 4 KByte pages, 4-way set associative, 128 entries
Data TLB1: 4 KByte pages, 4-way set associative, 256 entries
Data TLB1: 4 KByte pages, 4-way set associative, 64 entries
Data TLB: 4 KByte and 4 MByte pages, 4-way set associative, 8 entries
64-Byte Prefetching
128-Byte Prefetching
Unexpected end of sequence
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
DCOM not installed
The privilege "%s" is not held by the user.
Buffer overflow
Invalid UTF7
OLE control activation failed
2nd-level cache: 1 MBytes, 4-way set associative, 64 bytes line size
2nd-level cache: 128 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector
2nd-level cache: 256 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector
2nd-level cache: 512 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector
2nd-level cache: 1 MBytes, 8-way set associative, 64 bytes line size, 2 lines per sector
2nd-level cache: 2 MBytes, 8-way set associative, 64 byte line size
2nd-level cache: 512 KBytes, 2-way set associative, 64 byte line size
2nd-level cache: 512 KBytes, 8-way set associative, 64 byte line size
2nd-level cache: 256 KBytes, 8-way associative, 32 byte line size
2nd-level cache: 512 KBytes, 8-way associative, 32 byte line size
2nd-level cache: 1 MBytes, 8-way associative, 32 byte line size
2nd-level cache: 2 MBytes, 8-way associative, 32 byte line size
2nd-level cache: 512 KByte, 4-way set associative, 64 byte line size
2nd-level cache: 1 MByte, 8-way set associative, 64 byte line size
Instruction TLB: 4 KByte pages, 4-way set associative, 128 entries
Instruction TLB: 2 MByte pages, 4-way, 8 entries or 4 MByte pages, 4-way, 4 entries
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 128 Entries
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 256 Entries
Data TLB0: 4 MByte pages, 4-way set associative, 16 entries
Data TLB0: 4 KByte pages, 4-way associative, 16 entries
Data TLB0: 4 KByte pages, fully associative, 16 entries
Data TLB: 4 KByte and 4 MByte pages, 64 Entries
Data TLB: 4 KByte and 4 MByte pages, 128 Entries
Data TLB: 4 KByte and 4 MByte pages, 256 Entries
1st-level data cache: 16 KByte, 8-way set associative, 64 byte line size
1st-level data cache: 8 KBytes, 4-way set associative, 64 byte line size
1st-level data cache: 16 KBytes, 4-way set associative, 64 byte line size
1st-level data cache: 32 KBytes, 4-way set associative, 64 byte line size
Trace cache: 12 K-Ops, 8-way set associative
Trace cache: 16 K-Ops, 8-way set associative
Trace cache: 32 K-Ops, 8-way set associative
Trace cache: 64 K-Ops, 8-way set associative
No 2nd-level cache or, if processor contains a valid 2nd-level cache, no 3rd-level cache
2nd-level cache: 128 KBytes, 4-way set associative, 32 byte line size
2nd-level cache: 256 KBytes, 4-way set associative, 32 byte line size
2nd-level cache: 512 KBytes, 4-way set associative, 32 byte line size
2nd-level cache: 1 MBytes, 4-way set associative, 32 byte line size
2nd-level cache: 2 MBytes, 4-way set associative, 32 byte line size
3rd-level cache: 4 MBytes, 4-way set associative, 64 byte line size
3rd-level cache: 8 MBytes, 4-way set associative, 64 byte line size
3rd-level cache: 8 MByte, 8-way set associative, 64 byte line size
2nd-level cache: 4 MBytes, 16-way set associative, 64 byte line size
3rd-level cache: 6MByte, 12-way set associative, 64 byte line size
3rd-level cache: 8MByte, 16-way set associative, 64 byte line size
3rd-level cache: 16MByte, 16-way set associative, 64 byte line size
2nd-level cache: 6MByte, 24-way set associative, 64 byte line size
Instruction TLB: 4 KByte pages, 32 Entries
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 64 Entries
1st level data cache: 8 KBytes, 2-way set associative, 32 byte line size
Instruction TLB: 4 MByte pages, 4-way set associative, 4 entries
1st level data cache: 16 KBytes, 4-way set associative, 32 byte line size
1st level data cache: 24 KBytes, 6-way set associative, 64 byte line size
3rd level cache: 512 KBytes, 4-way set associative, 64 byte line size, 2 lines per sector
3rd level cache: 1 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector
3rd level cache: 2 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector
3rd level cache: 4 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector
1st level data cache: 32 KBytes, 8-way set associative, 64 byte line size
1st level instruction cache: 32 KBytes, 8-way set associative, 64 byte line size
2nd-level cache: 128 KBytes, 4-way set associative, sectored cache, 64-byte line size
2nd-level cache: 192 KBytes, 6-way set associative, sectored cache, 64-byte line size
2nd-level cache: 128 KBytes, 2-way set associative, sectored cache, 64-byte line size
2nd-level cache: 256 KBytes, 4-way set associative, sectored cache, 64-byte line size
2nd-level cache: 384 KBytes, 6-way set associative, sectored cache, 64-byte line size
2nd-level cache: 512 KBytes, 4-way set associative, sectored cache, 64-byte line size
Failed to retrieve tab at index %d
Failed to get object at index %d
Failed to set tab "%s" at index %d
Failed to set object at index %d
MultiLine must be True when TabPosition is tpLeft or tpRight
%d is an invalid PageIndex value. PageIndex must be between 0 and %d
No help keyword specified.
Failed to get ANSI replacement character
Null descriptor
Instruction TLB: 4 KByte pages, 4-way set associative, 32 entries
Instruction TLB: 4 MByte pages, 4-way set associative, 2 entries
Data TLB: 4 KByte pages, 4-way set associative, 64 entries
Data TLB: 4 MByte pages, 4-way set associative, 8 entries
Data TLB1: 4 MByte pages, 4-way set associative, 32 entries
1st level instruction cache: 8 KBytes, 4-way set associative, 32 byte line size
1st level instruction cache: 16 KBytes, 4-way set associative, 32 byte line size
Inactive Border
Inactive Caption
Inactive Caption Text
Info Background
Info Text
Menu Background
Menu Text
None
Scroll Bar
3D Dark Shadow
3D Light
Window Background
Window Frame
Window Text
Failed to clear tab control
Failed to delete tab at index %d
Sky Blue
Cream
Medium Gray
Active Border
Active Caption
Application Workspace
Background
Button Face
Button Highlight
Button Shadow
Button Text
Caption Text
Default
Gray Text
Highlight Background
Highlight Text
Maroon
Green
Olive
Navy
Purple
Teal
Gray
Silver
Red
Lime
Yellow
Blue
Fuchsia
Aqua
White
Money Green
Shift+
Ctrl+
Alt+
Clipboard does not support Icons
Cannot open clipboard
Text exceeds memo capacity
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Unable to find a Table of Contents
No help found for %s
No context-sensitive help installed
No topic-based help system installed
Black
Yes to &All
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Del
Icons
Bitmaps
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
OK
Cancel
&Yes
&No
&Help
&Close
&Ignore
&Retry
Abort
&All
Cannot drag a form
Metafiles
Enhanced Metafiles
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
%s property out of range
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Tab position incompatible with current tab style
Tab style incompatible with current tab position
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Invalid pixel format
Scan line index out of range
Cannot change the size of an icon
Invalid operation on TOleGraphic
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Invalid stream format
'%s' is an invalid mask at (%d)
''%s'' is not a valid component name
Invalid property value
Invalid property element: %s
Invalid property path
Invalid property type: %s
Invalid property value
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Unable to create directory
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Custom variant type (%s%.4x) is out of range
Custom variant type (%s%.4x) already used by %s
Custom variant type (%s%.4x) is not usable
Too many custom variant types have been registered
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
%s (%s, line %d)
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
'%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
'%s' is not a valid boolean value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied

Version Info

TLS Callbacks

StartAddressOfRawData 0x615000
EndAddressOfRawData 0x615024
AddressOfIndex 0x6030b4
AddressOfCallbacks 0x616010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section BSS has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Multiple nodes using the name Version Info in a dictionary.